Skip to content

Commit

Permalink
Fix Acronis Cyber Protect Connect name
Browse files Browse the repository at this point in the history
  • Loading branch information
wikijm committed Nov 14, 2024
1 parent eca4d36 commit 13d5201
Show file tree
Hide file tree
Showing 3 changed files with 12 additions and 12 deletions.
Original file line number Diff line number Diff line change
@@ -1,4 +1,4 @@
title: Potential Acronic Cyber Protect (Remotix) RMM Tool Network Activity
title: Potential Acronis Cyber Protect (Remotix) RMM Tool Network Activity
logsource:
product: windows
category: network_connection
Expand All @@ -12,13 +12,13 @@ detection:
condition: selection
id: a7ed0eb9-3d99-47ee-a335-3162430f519c
status: experimental
description: Detects potential network activity of Acronic Cyber Protect (Remotix)
description: Detects potential network activity of Acronis Cyber Protect (Remotix)
RMM tool
author: LOLRMM Project
date: 2024/08/07
tags:
- attack.execution
- attack.t1219
falsepositives:
- Legitimate use of Acronic Cyber Protect (Remotix)
- Legitimate use of Acronis Cyber Protect (Remotix)
level: medium
Original file line number Diff line number Diff line change
@@ -1,4 +1,4 @@
title: Potential Acronic Cyber Protect (Remotix) RMM Tool Process Activity
title: Potential Acronis Cyber Protect (Remotix) RMM Tool Process Activity
logsource:
product: windows
category: process_creation
Expand All @@ -10,13 +10,13 @@ detection:
condition: selection
id: 9b9647ab-97cc-4c7c-8540-5c1c1c8000c4
status: experimental
description: Detects potential processes activity of Acronic Cyber Protect (Remotix)
description: Detects potential processes activity of Acronis Cyber Protect (Remotix)
RMM tool
author: LOLRMM Project
date: 2024/08/07
tags:
- attack.execution
- attack.t1219
falsepositives:
- Legitimate use of Acronic Cyber Protect (Remotix)
- Legitimate use of Acronis Cyber Protect (Remotix)
level: medium
Original file line number Diff line number Diff line change
@@ -1,5 +1,5 @@
Name: Acronic Cyber Protect (Remotix)
Description: Acronic Cyber Protect (Remotix) is a remote monitoring and management
Name: Acronis Cyber Protect (Remotix)
Description: Acronis Cyber Protect (Remotix) is a remote monitoring and management
(RMM) tool. More information will be added as it becomes available.
Author: ''
Created: ''
Expand Down Expand Up @@ -32,11 +32,11 @@ Artifacts:
- connect.acronis.com
Ports: []
Detections:
- Sigma: https://github.com/magicsword-io/LOLRMM/blob/main/detections/sigma/acronic_cyber_protect__remotix__network_sigma.yml
Description: Detects potential network activity of Acronic Cyber Protect (Remotix)
- Sigma: https://github.com/magicsword-io/LOLRMM/blob/main/detections/sigma/acronis_cyber_protect__remotix__network_sigma.yml
Description: Detects potential network activity of Acronis Cyber Protect (Remotix)
RMM tool
- Sigma: https://github.com/magicsword-io/LOLRMM/blob/main/detections/sigma/acronic_cyber_protect__remotix__processes_sigma.yml
Description: Detects potential processes activity of Acronic Cyber Protect (Remotix)
- Sigma: https://github.com/magicsword-io/LOLRMM/blob/main/detections/sigma/acronis_cyber_protect__remotix__processes_sigma.yml
Description: Detects potential processes activity of Acronis Cyber Protect (Remotix)
RMM tool
References:
- https://kb.acronis.com/content/47189
Expand Down

0 comments on commit 13d5201

Please sign in to comment.